Perhaps the fallout would be good for computer security, as it would stop corporations from making boneheaded security decisions. Pain seems to be the only way to make corporations evolve anyways.
Perhaps the fallout would be good for computer security, as it would stop corporations from making boneheaded security decisions. Pain seems to be the only way to make corporations evolve anyways.
MS deserves some responsibility for causing this. And "take your entire AD network down for some amount of time and break backwards compatibility" is not a reasonably fix.
Microsoft certainly screwed up here, but all this guy did was... exist.
By effectively configuring AD / Windows to DDoS the domain, on multiple protocols, MS deprived him of usability.
Seems pretty open & shut on loss of value.
To put it in perspective, dating.com sold for 1.75m.
That was 10 years ago.
"myworld.com" sold for 1.2m in 2017, "jade.com" sold for 1.25m, "vivo.com" went for 2.1m
In 2019, "voice.com" sold for 30 million usd.
"California.com" sold for $3m this past year, so let's not pretend that much has shifted in the market for these domain names in the span of this decade. $1.7m is a hefty sum for a domain name that isn't even a word.
But it's an irrelevant debate.
My point is that the counterargument against any lawsuit would be that the high value of the domain name "corp.com" comes from the Microsoft issue, so it'd be pretty tough to argue that the owner was harmed by Microsoft.
He has no obligation to M$FT or any of their customers.
He has an informal agreement with a informal group of organizations to respect his decision of what records to return in response to DNS requests. No one is obligated to follow that agreement. This form of abuse of that informal agreement should result in the group of organizations unilaterally terminating that agreement.
It’s a legally binding agreement. I guess we should start yanking peoples’ homes because all they have is an “informal agreement” with the seller?
He has some legal agreement with his registrar, and maybe indirectly with ICAAN, but that legal agreement means jack shit to DNS providers, who are the ones that ultimately matter.
For an example of DNS providers already using this fact for the public good, see AdGuard DNS
The fact that a criminal may acquire them and/or use them for nefarious purposes does not mean selling them is a problem.
[1]: https://www.namecheap.com/domains/registration/results.aspx?...
Otherwise, you end up with a world where anyone who comes into possession of a dangerous item is obligated to potentially keep it forever and force all of their descendants to keep it forever.
> O’Connor said he hopes Microsoft Corp. will buy it, but fears they won’t and instead it will get snatched up by someone working with organized cybercriminals or state-funded hacking groups bent on undermining the interests of Western corporations.
They would try to alert companies using a domain they didn't own for communications to their customers that this was a bad idea, and soon after got nastygrams from the company's lawyers saying they'd stolen their intellectual property and wiretapped their communications.
http://voices.washingtonpost.com/securityfix/2008/03/they_to...
The only real difference in the corp.com case is that instead of just one BigCorp, it's one BigCorp that's gotten a bunch of other SmallCorps and BigCorps to all incorrectly list the same address too.
On the same general note, "a business listed my phone number as theirs and refuses to change it" stories are pretty common, and often have the same "the business refuses to change it" quality.
https://arstechnica.com/tech-policy/2016/08/kansas-couple-su...
It's their house, they can sell it and the associated addresses to whomever they see fit
In his position, I would absolutely capitalize on the domain; consider that selling is one of the more harmless ways that value could easily be extracted from it. Maybe if I were a billionaire I would consider giving it away, but even then I would rather take the money and donate it than leave it in Microsoft's pocket, considering this is 100% their screwup.
Instead they leaned on free benevolence from this guy.
An asking price of $1.7 million is hardly "taking advantage" of a $286 billion company. Microsoft hoist themselves by their own petard here by letting this problem sit for 26 years: that's only about $65,000 per year, which is more than reasonable pay for somebody who's been effectively giving them free IT services that entire time.
And as an aside, your stated market cap for Microsoft is off by more than a trillion dollars.
Yes. However, whoever managed raise 1.7 mil probably did through earning it. Money goes both ways.
Your statement is completely ridiculous. There's no requirement to "work" or provide benefit to society before you can sell something you rightfully and legally purchased.
Everyone investing in the stock market is the first to buy something at a lower price. Do they not own the stock? What work did they do when it increases in price? Do they have to prove to society that they're a good person when they offer to sell the stock?
> "If a decision is made you can't trade in them"
Ok, but it hasn't been made. Ownership can be sold and transferred so that's what's happening.
When you buy a share of a company, it's also just assigned to you. But you still own it.
https://freedom-to-tinker.com/2008/10/18/kentucky-vs-141-dom...
They're intangible property (I never said they were tangible), though that distinction doesn't really make a big difference here anyway since the physicality of the property isn't relevant.
Criticism of loose capitalism isn't automatically ridiculous.
>There's no requirement to "work" or provide benefit to society before you can sell something.
Well, obviously some people think that that is a problem with our current system of wealth distribution :)
Some people believe ridiculous things. Doesn't make it any less true, and I've yet to hear of any magic utopia system that's any better than capitalism in reality.
Except in my hypothetical example your response makes you sound like some sort of communist outraged by the profit your neighbor made off their house, when you bought the decidedly unfamous one next to it.
> His is just trying to extort society for that money by threatening to help criminals if we don't give it to him.
Is he? Where's your proof? Perhaps he's just sharing his very novel experience of a property he owns that the world honestly should know about for security reasons. What if this man dies in a few months and we didn't know about this, then his kids sell it to the NSA or Russia, would you rather that?
If everything this "security team" from the article has said is true, this domain is Persona Non Grata. Its an armed nuclear warhead. There is no positive outcome for this story that begins with "And then the domain was bought by".
Its Microsoft's "responsibility" to "clean up after their mess". No; We're beyond fighting about who should take responsibility. Throw the ball in Microsoft's court and they'll offer $20k. Throw the ball back to O'Conner and he'll say it's worth far more. He throws the ball to the market. Terrorists notice that, wait, actually, that ball is a nuke. Cool, its at auction; Microsoft now has to pay millions of dollars. So our two options are: Microsoft buys the thing and we're safe, or they don't and we're fucked, and a couple people on reddit are mad at Microsoft for cheaping out, but they live on like it never happened, and we all forget for 18 months until, one day, at the top of hackernews we get a nice new HaveIBeenPwned.
At this point, this domain is like example.com; IANA owns that one. Its too generic. Its used in documentation. People mistake it for being meaningful. The only reason it hasn't caused issues is because the owner has, all thanks to him, not intended to cause harm to the public. But we're now in a place where we can do something about it, and this domain should be removed from public registration.
I feel opposite. It is definitely MS's responsibility, but they don't care because they are not going to be pawned. Its the poor users who MS suggested to use corp as their AD domain without buying that domain in the first place.
Every time any corp fks up, the people have to pay for it (maybe by getting hacked, or being saved by state) and corps don't care.
> Its too generic
Right, and who chose it ? This domain is like example.com except it ain't because people don't mistake it for being meaningful, MS advised people to use it explicitly.
More to your point, this domain is now "too generic" because Microsoft made it so. example.com is going to be used by a wide collection of people, "corp.com" really only has this issue because of Microsoft, there's no generic reason why people would use "corp.com" in the same way they use "example.com".
Microsoft created this situation and effectively made that domain toxic, surely it's on them to fix it?
Be very careful about that use of language; your rights, as a citizen of whatever country you live in, are generally limited and legally defined. Domain name ownership certainly does not qualify as a Right.
Big corps are not usually the ones that are affected the most.